Guide 04 — Coverage Rollout (Per-Layer Onboarding)¶
How each layer of the estate gets monitored on the new platform. Work top to bottom — colo first (it's the gap list), then metro, then venues.
1. Proxmox cluster¶
- Create a read-only API token on the cluster (
PVEAuditorrole is enough). - One Zabbix host object represents the cluster (agentless), templated with Proxmox VE by HTTP; token in host macros.
- LLD auto-discovers nodes and all VMs: CPU, memory, disk, VM up/down, cluster quorum, node status. This is hypervisor-level VM coverage for free — every VM gets basic monitoring without an agent.
- Each physical node is also a NetBox device (
hypervisorrole) with the Linux agent template for OS-level detail (disks, SMART via agent 2, network).
2. Ceph¶
- Enable the Ceph RESTful/mgr module and create a monitoring user per the template docs.
- Zabbix agent 2 on one or two monitor nodes with Ceph by Zabbix agent 2.
- Coverage: cluster health status, OSD up/in counts, per-pool usage and IOPS, capacity forecasting from trends.
- Key triggers: health
WARN/ERR, OSD down, pool >80% full, capacity trend projected full within 90 days.
3. Physical SQL servers¶
- OS layer: Zabbix agent 2 (Linux or Windows template).
- DB layer: native template per flavour — MSSQL by ODBC, PostgreSQL by agent 2, or MySQL by Zabbix agent 2 — with a least-privilege monitoring account. (Open question in the spec: confirm flavour.)
- Coverage: connections, replication/AG state if clustered, long queries, backup age (agent item checking last-backup timestamp is worth adding).
4. OPNsense firewalls¶
- Install the
os-zabbixagentplugin from the OPNsense plugin repo; agent template covers OS, states table, gateway status. - SNMP for interface counters if preferred for uniformity with network kit.
- Monitor every venue VPN tunnel from here: tunnel up/down + throughput items, one per venue. These become the parents in the dependency tree (Guide 05).
5. MikroTik routers (venues + metro)¶
- Enable SNMPv3 estate-wide (scripted via RouterOS API/SSH across all devices — one credential set, stored as Zabbix secret macros).
- Official MikroTik by SNMP template: auto-detects model, discovers interfaces, CPU/mem, PSU/temp where supported.
- Venue routers are the anchor host per venue — their ICMP/SNMP reachability trigger is the parent for everything else in the venue.
6. Metro/core network kit¶
- SNMPv3 + vendor-appropriate templates. This replaces LibreNMS.
- Interface LLD with sensible filters (physical + uplinks yes; every VLAN SVI no) to keep item counts sane.
- Traffic/error/discard triggers on uplinks; topology dependencies per Guide 05.
7. UniFi switches and APs¶
- Enable SNMP in the UniFi controller (applies to all adopted devices).
- SNMP templates give per-device status, uplink traffic, basic radio stats.
- Supplement with HTTP checks against the controller API for what SNMP lacks: AP adoption state, client counts, firmware. (Open question: controller self-hosted vs cloud decides how this is queried.)
- Don't over-monitor APs — up/down, uplink, client count, and radio utilisation is the right level for 200 APs.
8. Tills (Windows, active agents)¶
- Scripted MSI install of Zabbix agent 2:
msiexec /i zabbix_agent2.msi /qn SERVER=<zbx> SERVERACTIVE=<zbx> HOSTNAME=<netbox-name> TLSCONNECT=psk ...Hostname must match the NetBox device name (Guide 01 §4). Use PSK encryption — till traffic crosses the VPN. - Deploy via whatever reaches tills today (RMM, GPO, or a USB-stick-and-checklist pilot venue first).
- Trimmed template (clone of Windows by Zabbix agent, active): agent availability (= till up), disk space, CPU/memory sustained, uptime (detects unexpected reboots and never-rebooted machines).
- Active mode means tills initiate the connection — zero central polling load and no inbound firewall rules at venues.
Onboarding verification per wave¶
After each wave: every synced host green (no unsupported items), data flowing on spot-checked items, triggers test-fired for one device per role, and the venue/metro dependency chain verified by a controlled test (Guide 05 §4).